CVE-2025-42903

MEDIUM

SAP Financial Service Claims Management - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality with no impact on integrity or availability.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-204
Status published
Products (7)
SAP_SE/SAP Financial Service Claims Management 108
SAP_SE/SAP Financial Service Claims Management 109
SAP_SE/SAP Financial Service Claims Management 804
SAP_SE/SAP Financial Service Claims Management 805
SAP_SE/SAP Financial Service Claims Management 806
SAP_SE/SAP Financial Service Claims Management INSURANCE 803
SAP_SE/SAP Financial Service Claims Management S4CEXT 107
Published Oct 14, 2025
Tracked Since Feb 18, 2026